Tag · secondary filter
Cybersecurity
Machine attestation, continuous compliance, threat modeling, insider risk, and why paperwork-based assurance keeps failing.
24 pieces, grouped by format
November 1, 2024
Why Machine Attestation is Key in the Age of CMMC
Under the DoD’s CMMC Program, maintaining continuous compliance is crucial, and machine attestation provides the consistency and accuracy human checks can’t match. By automating compliance tracking, contractors can ensure real-time verification, creating a robust audit trail and reducing compliance risks across contract lifecycles.
June 19, 2024
Transforming Healthcare with Advanced Applications of High-Performance Computing
High-performance computing (HPC) has revolutionized healthcare, particularly in fields like oncology and biomedical engineering, where it enables researchers to perform complex simulations and genetic analyses far quicker than traditional methods. The transition from conventional numerical analysis to dynamic generative AI has further expanded the capabilities of this powerful technology, not only enhancing patient care but also reshaping expectations for rapid medical innovation.
September 30, 2023
Embrace Compliance as Code
Exploring the benefits of transitioning to a 'compliance as code' model by reflecting on successful implementations of other 'as code' models.
April 25, 2004
Online social and professional networking
For the past few months I’ve been experimenting with the new social networking tools that are available online. The one I’ve found most useful (relatively speaking) is LinkedIn. Internetworking websites and software are…
March 21, 2004
AOP, the evolution of OOP
Over the past couple of years I’ve been teaching courses on Aspect-oriented Programming (AOP) and find that developers have a hard time grasping the concepts (as did I when I first encountered it). If we use an analogy, AOP is…
April 19, 2025
How Senior Officials Should Think About AI Roadmaps
AI roadmaps are not just technical plans; they are trust strategies, implementation guides, and accountability tools. In this post, Shahid Shah outlines the essential components of AI roadmaps for governments and mission-driven organizations, and how to evaluate if your roadmap is truly ready for execution.
September 6, 2024
Healthcare’s Cybersecurity Crisis: Leadership Challenges and Strategic Solutions
Healthcare's cybersecurity crisis is critical, with outdated defenses exposing patient data and trust. Zero Trust is now mandatory, and delays in breach detection can cause immense damage. Effective leadership, including fractional CISOs, is essential for modern defense. Inaction isn't an option, proactive steps are necessary to safeguard against sophisticated threats.
June 6, 2024
From Vulnerability to Strength: The Role of CISO Services in Cyber Resilience
There was a time when no one really needed a CISO. Today, an organization would be dangerously insane not to have one. And that CISO had better be top-notch. The role of the Chief Information Security Officer (CISO) has evolved significantly from being solely a technology-focused professional to becoming a strategic business leader
September 10, 2023
Enterprise Architecture: A Guide for Tech Leaders
Enterprise architecture is a strategic framework that helps organizations align their business and technology strategies. It provides a holistic view of the organization’s structure, processes, and systems, enabling effective…
September 1, 2023
The Benefits of Hiring a Fractional Chief Technology Officer
A Fractional Chief Technology Officer (CTO) is a senior-level executive who provides part-time, strategic guidance and leadership in the technology domain. Unlike a full-time CTO, a fractional CTO works on a contract basis,…
June 1, 2023
The Importance of Chief Information Security Officers in Federal Government Contracts
A Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining the enterprise vision, strategy, and program to ensure information assets and technologies are adequately…
May 21, 2004
Exploiting Software: How to Break Code
Last night I invited Dr. Gary McGraw to give a talk on his new book Exploiting Software: How to Break Code at our monthly IEEE Computer Society Northern Virginia Chapter meeting. We had almost 100 people attend a wonderful…
August 20, 2024
CTOs: The Overlooked Asset in a VC's Portfolio
Venture capitalists often overlook the strategic importance of a Chief Technology Officer (CTO), mistaking technical co-founders as a simple checkbox. A seasoned CTO bridges vision and execution, aligning tech strategy with business goals, mitigating risks, and driving innovation, key factors that can make or break a startup's success.
September 26, 2023
Systems that require human attestation to prove compliance are not secure
While a system may meet all the necessary regulations and standards, it can still be vulnerable to threats and attacks because of human attestation.
June 1, 2022
Compliant Insecurity in Government Agencies and Contractors
I challenge the conventional wisdom on cybersecurity, focusing on the problem of 'compliant insecurity'.
January 6, 2006
If engineers or database administrators can access your data, it’s not secure
There is a general misconception in the IT community that their database servers are somehow their most secure systems and that *because* they are secure their customers data and their own financial information is safe. Let me…
September 8, 2006
NIST Releases Recommendations for Securing Web Services
NIST Special Publication 800-95 addresses security needs for networks in which automated Web services are being deployed in service-oriented architectures. It’s only in draft but it covers the basics fairly well. If you’re…
May 22, 2006
Threat Modeling Web Applications
I just ran across Microsoft’s Threat Modeling Web Applications article on MSDN. Worth checking out if you’re writing secure web apps.
February 25, 2006
Securing Your Desktops from Pod Slurping
The EMR and HIPAA blog has posted additional information on “pod slurping”: Securing Your Desktops – Pod Slurping. He’s started a good discussion out there and we should join in to see if we can talk about policies health IT…
December 5, 2005
Java Surpasses C++ on SourceForge
Since eWeek reports that Java surpassed C++ on SourceForge all us Java architects can now rest assured that we have job security. 🙂
November 19, 2005
Microsoft Touts New Ajax Tools
There’s a nice interview on Microsoft’s new found respect for AJAX: Q&A: Microsoft Touts New Ajax Tools. Microsoft says:
October 12, 2005
Attitudes of Americans Regarding Personal Health Records
The Markle Foundation has released the *Attitudes of Americans Regarding Personal Health Records and Nationwide Electronic Health Information Exchange* research report. It’s numbers are bit lower than the numbers from the 2004…
October 9, 2005
HHS National Health Information Infrastructure contract awards forthcoming
Those of us involved in the healthcare IT (HIT) market may want to keep an eye on these new awards and other RFIs related to it. According to Government Computer News (GCN):
October 27, 2004
New version of PuTTY is out
If you’re a heavy user of PuTTY, like I am, you’ll want to grab the latest release which fixes a major security hole. In case you don’t already know, PuTTY is a free Windows SSH and Telnet client (which is actually now…
