Software Security Maturity Models: A Source Review
Jun 20, 2026 / · 6 min read · software security bsimm owasp samm isa-cmm secure development information assurance ·Software Security Maturity Models: A Source Review Building Security in Maturity Model (BSIMM) The Building Security in Maturity Model (BSIMM), is a guideline that outlines 113 activities organized into 12 different sections which assist in the software security framework. The document is broken into two parts. The …
Read MoreComparing BSIMM and SAMM Software Security Models
Jun 19, 2026 / · 31 min read · software security bsimm owasp samm capability maturity model information assurance secure development ·Comparing BSIMM and SAMM Software Security Models The role of the information assurance security program as described by Sadiku, Alam, & Musa (2017) is the practice of protecting and defending information systems by ensuring their availability, confidentiality, integrity, authentication, and non-repudiation. …
Read MoreApplying the ISA-CMM: A Cloud E-Store Case Study
Jun 18, 2026 / · 4 min read · isa-cmm information assurance cloud security aws security assessment capability maturity model ·Applying the ISA-CMM: A Cloud E-Store Case Study Company A (CA) is a major supplier of satellite imagery to commercial, federal and defense vertical markets. The organization launched an e-commerce website on the Internet or an estore enabling customers to navigate, review and purchase satellite imagery. This applied …
Read MoreSecurity Risk Assessment: Essential Reference Sources
Jun 17, 2026 / · 5 min read · security risk assessment risk analysis fair methodology information security risk management information assurance ·Security Risk Assessment: Essential Reference Sources Measuring and Managing Information Risk: A FAIR Approach This book assists the reader in understanding how to put to use the Factor Analysis of Information Risk (FAIR) methodology. The book consists of topics on measuring and managing information risk and provides …
Read MoreSocial Engineering Tactics Behind a $24,000 Heist
Jun 16, 2026 / · 2 min read · social engineering penetration testing physical security two-factor authentication security awareness information security ·Social Engineering Tactics Behind a $24,000 Heist Reflecting on the readings and video few actions stuck with me. The first is social engineering is an critical skill to gain access to information in organizations. I have received many cold calls over the years with interest in collecting information about the …
Read MoreFull Content Data in Network Security Monitoring
Jun 7, 2026 / · 3 min read · network security monitoring full content data intrusion detection incident response packet capture information security ·Full Content Data in Network Security Monitoring Security is the method of keeping an acceptable level of risk. The security process revolves around four steps: assessment, protection, detection, and response as described by Bejtlich (2004). The step of the process, assessment, is a groundwork needed for the other …
Read MoreSecurity Risk Assessment: Planning and Key Metrics
Jun 6, 2026 / · 4 min read · security risk assessment security metrics risk analysis information assurance project planning information security ·Security Risk Assessment: Planning and Key Metrics The security assessment considerations as described by Landoll (2016), at a high level, includes six phases. The phases are the project definition, the project preparation, gathering the data, analyzing the risk, mitigation of risks and the recommendations or …
Read MoreSecurity Awareness Training and ISA Capability Maturity
Jun 5, 2026 / · 3 min read · security awareness information assurance security training isa-cmm security policy information security ·Security Awareness Training and ISA Capability Maturity Technology is constantly changing. Security technology is getting better and making jobs easier as described by Peltier (2013). Bad actors continue to cause issues no matter what new security is introduced. It is a constant cycle. Security awareness includes many …
Read MoreAlert Data and NSM Tools for Intrusion Detection
Jun 4, 2026 / · 3 min read · alert data network security monitoring intrusion detection nsm tools ids information security ·Alert Data and NSM Tools for Intrusion Detection Network Security Monitoring (NSM) data that has been previously discussed are full content data (FCD), session data and statistical data. The result of an NSM specific data is to identify decisions based on views of network traffic. The NSM tool assists the analyst(s) …
Read MorePlanning an Affiliate E-Commerce Catalog Business
Jun 3, 2026 / · 41 min read · affiliate marketing e-commerce management information systems enterprise systems it infrastructure business plan data management ·Planning an Affiliate E-Commerce Catalog Business Katalogs Plus is a new business planning to launch in the next year. The company mission is to build e-commerce mobile applications and websites that sell merchants products and services. Affiliate marketing product and service data feeds will be used to generate …
Read More