Bill Brown:Thoughts and Reference Material Online
open-menu closeme
Home
About
Contact Us
Privacy Statement
rss linkedin
  • Software Security Maturity Models: A Source Review

    calendar Jun 20, 2026 / Jun 20, 2026 · 6 min read · software security bsimm owasp samm isa-cmm secure development information assurance  ·
    Share on: twitter facebook linkedin copy

    Software Security Maturity Models: A Source Review Building Security in Maturity Model (BSIMM) The Building Security in Maturity Model (BSIMM), is a guideline that outlines 113 activities organized into 12 different sections which assist in the software security framework. The document is broken into two parts. The …


    Read More
  • Comparing BSIMM and SAMM Software Security Models

    calendar Jun 19, 2026 / Jun 20, 2026 · 31 min read · software security bsimm owasp samm capability maturity model information assurance secure development  ·
    Share on: twitter facebook linkedin copy

    Comparing BSIMM and SAMM Software Security Models The role of the information assurance security program as described by Sadiku, Alam, & Musa (2017) is the practice of protecting and defending information systems by ensuring their availability, confidentiality, integrity, authentication, and non-repudiation. …


    Read More
  • Applying the ISA-CMM: A Cloud E-Store Case Study

    calendar Jun 18, 2026 / Jun 20, 2026 · 4 min read · isa-cmm information assurance cloud security aws security assessment capability maturity model  ·
    Share on: twitter facebook linkedin copy

    Applying the ISA-CMM: A Cloud E-Store Case Study Company A (CA) is a major supplier of satellite imagery to commercial, federal and defense vertical markets. The organization launched an e-commerce website on the Internet or an estore enabling customers to navigate, review and purchase satellite imagery. This applied …


    Read More
  • Security Risk Assessment: Essential Reference Sources

    calendar Jun 17, 2026 / Jun 20, 2026 · 5 min read · security risk assessment risk analysis fair methodology information security risk management information assurance  ·
    Share on: twitter facebook linkedin copy

    Security Risk Assessment: Essential Reference Sources Measuring and Managing Information Risk: A FAIR Approach This book assists the reader in understanding how to put to use the Factor Analysis of Information Risk (FAIR) methodology. The book consists of topics on measuring and managing information risk and provides …


    Read More
  • Social Engineering Tactics Behind a $24,000 Heist

    calendar Jun 16, 2026 / Jun 20, 2026 · 2 min read · social engineering penetration testing physical security two-factor authentication security awareness information security  ·
    Share on: twitter facebook linkedin copy

    Social Engineering Tactics Behind a $24,000 Heist Reflecting on the readings and video few actions stuck with me. The first is social engineering is an critical skill to gain access to information in organizations. I have received many cold calls over the years with interest in collecting information about the …


    Read More
  • Full Content Data in Network Security Monitoring

    calendar Jun 7, 2026 / Jun 7, 2026 · 3 min read · network security monitoring full content data intrusion detection incident response packet capture information security  ·
    Share on: twitter facebook linkedin copy

    Full Content Data in Network Security Monitoring Security is the method of keeping an acceptable level of risk. The security process revolves around four steps: assessment, protection, detection, and response as described by Bejtlich (2004). The step of the process, assessment, is a groundwork needed for the other …


    Read More
  • Security Risk Assessment: Planning and Key Metrics

    calendar Jun 6, 2026 / Jun 7, 2026 · 4 min read · security risk assessment security metrics risk analysis information assurance project planning information security  ·
    Share on: twitter facebook linkedin copy

    Security Risk Assessment: Planning and Key Metrics The security assessment considerations as described by Landoll (2016), at a high level, includes six phases. The phases are the project definition, the project preparation, gathering the data, analyzing the risk, mitigation of risks and the recommendations or …


    Read More
  • Security Awareness Training and ISA Capability Maturity

    calendar Jun 5, 2026 / Jun 7, 2026 · 3 min read · security awareness information assurance security training isa-cmm security policy information security  ·
    Share on: twitter facebook linkedin copy

    Security Awareness Training and ISA Capability Maturity Technology is constantly changing. Security technology is getting better and making jobs easier as described by Peltier (2013). Bad actors continue to cause issues no matter what new security is introduced. It is a constant cycle. Security awareness includes many …


    Read More
  • Alert Data and NSM Tools for Intrusion Detection

    calendar Jun 4, 2026 / Jun 7, 2026 · 3 min read · alert data network security monitoring intrusion detection nsm tools ids information security  ·
    Share on: twitter facebook linkedin copy

    Alert Data and NSM Tools for Intrusion Detection Network Security Monitoring (NSM) data that has been previously discussed are full content data (FCD), session data and statistical data. The result of an NSM specific data is to identify decisions based on views of network traffic. The NSM tool assists the analyst(s) …


    Read More
  • Planning an Affiliate E-Commerce Catalog Business

    calendar Jun 3, 2026 / Jun 7, 2026 · 41 min read · affiliate marketing e-commerce management information systems enterprise systems it infrastructure business plan data management  ·
    Share on: twitter facebook linkedin copy

    Planning an Affiliate E-Commerce Catalog Business Katalogs Plus is a new business planning to launch in the next year. The company mission is to build e-commerce mobile applications and websites that sell merchants products and services. Affiliate marketing product and service data feeds will be used to generate …


    Read More
    • ««
    • «
    • 1
    • 2
    • 3
    • 4
    • 5
    • »
    • »»

Disclaimer

The opinions expressed on this site are my own personal opinions and do not represent my employer’s view in any way.

Recent Posts

  • Software Security Maturity Models: A Source Review
  • Comparing BSIMM and SAMM Software Security Models
  • Applying the ISA-CMM: A Cloud E-Store Case Study
  • Security Risk Assessment: Essential Reference Sources
  • Social Engineering Tactics Behind a $24,000 Heist
  • Full Content Data in Network Security Monitoring
  • Security Risk Assessment: Planning and Key Metrics
  • Security Awareness Training and ISA Capability Maturity

Categories

BILL BROWN 91 INFORMATION SECURITY MANAGEMENT 16 DATABASE SYSTEMS 13 INFORMATION ASSURANCE 11 PROJECT MANAGEMENT 9 COMPUTER NETWORKS 8 ORACLE RAC 8 INFORMATION ASSURANCE CAPABILITY MATURITY AND APPRAISALS 4 INTRUSION DETECTION AND INCIDENT HANDLING 4 MANAGEMENT INFORMATION SYSTEMS 4 INFORMATION ASSURANCE ASSESSMENT AND EVALUATION 3 JUNK MAIL 2 PERSONAL 2 RED HAT 2
All Categories
BILL BROWN91 COLDFUSION1 COMPUTER NETWORKS8 DATA ANALYTICS1 DATABASE SYSTEMS13 INFORMATION ASSURANCE11 INFORMATION ASSURANCE ASSESSMENT AND EVALUATION3 INFORMATION ASSURANCE CAPABILITY MATURITY AND APPRAISALS4 INFORMATION SECURITY MANAGEMENT16 INTRUSION DETECTION AND INCIDENT HANDLING4 JUNK MAIL2 LACROSSE1 MANAGEMENT INFORMATION SYSTEMS4 ORACLE RAC8 PERSONAL2 PROJECT MANAGEMENT9 RED HAT2 TELECOMMUNICATIONS AND NETWORK SECURITY1 VMWARE1
[A~Z][0~9]

Series

INFORMATION SECURITY MANAGEMENT 16 DATABASE SYSTEMS 13 INFORMATION ASSURANCE 11 PROJECT MANAGEMENT 9 COMPUTER NETWORKS 8 ORACLE RAC 8 INFORMATION ASSURANCE CAPABILITY MATURITY AND APPRAISALS 4 INTRUSION DETECTION AND INCIDENT HANDLING 4 MANAGEMENT INFORMATION SYSTEMS 4 INFORMATION ASSURANCE ASSESSMENT AND EVALUATION 3 JUNK MAIL 2 PERSONAL 2 RED HAT 2 COLDFUSION 1
All Series
COLDFUSION1 COMPUTER NETWORKS8 DATA ANALYTICS1 DATABASE SYSTEMS13 INFORMATION ASSURANCE11 INFORMATION ASSURANCE ASSESSMENT AND EVALUATION3 INFORMATION ASSURANCE CAPABILITY MATURITY AND APPRAISALS4 INFORMATION SECURITY MANAGEMENT16 INTRUSION DETECTION AND INCIDENT HANDLING4 JUNK MAIL2 LACROSSE1 MANAGEMENT INFORMATION SYSTEMS4 ORACLE RAC8 PERSONAL2 PROJECT MANAGEMENT9 RED HAT2 TELECOMMUNICATIONS AND NETWORK SECURITY1 VMWARE1
[A~Z][0~9]

Tags

INFORMATION SECURITY 17 INFORMATION ASSURANCE 16 RISK MANAGEMENT 11 DATA-MANAGEMENT 10 PROJECT MANAGEMENT 10 SECURITY 8 CYBERSECURITY 7 ORACLE 7 PHYSICAL SECURITY 7 ACCESS CONTROL 6 AGILE 5 DATABASE-PROGRAMMING 5 INCIDENT-RESPONSE 5 RAC 5
All Tags
ACCESS CONTROL6 ACTIVE SHOOTER TRAINING1 ADMINISTRATION1 AFFILIATE MARKETING2 AFFORDABLE CARE ACT1 AGILE5 AGILE-DEVELOPMENT1 ALERT DATA1 ALGORITHMS1 ASM2 AUTHENTICATION3 AUTHORIZATION1 AWARENESS1 AWS3 BACKGROUND CHECK1 BIG DATA1 BOULDER1 BOULDER COLORADO1 BSIMM2 BURN-DOWN-CHART1 BURN-UP-CHART1 BUSINESS CONTINUITY2 BUSINESS INTELLIGENCE1 BUSINESS OPERATIONS1 BUSINESS PLAN1 BUSINESS STRATEGY1 CAPABILITY MATURITY1 CAPABILITY MATURITY MODEL2 CELL BROADCAST1 CELLULAR TECHNOLOGY1 CFLOOP1 CHRISTCHURCH1 CHRISTCHURH NEW ZEALAND1 CIA TRIAD1 CICD-PIPELINE1 CLEAN DESK1 CLOUD SECURITY2 CLUSTER1 COLD FUSION1 COLDFUSION1 COLORADO2 COMMUNICATION3 COMPETITIVE STRATEGY1 COMPLIANCE4 CONFIDENTIALITY1 CONNECTIVITY3 CONTROLS1 CRISIS MANAGEMENT1 CRITICAL THINKING1 CRYPTOGRAPHY1 CULTURE CHANGE1 CURRENTROW1 CURSORS1 CUSTOMER INSIGHTS1 CYBERSECURITY7 DATA ANALYTICS2 DATA COMMUNICATION2 DATA PROTECTION1 DATA SECURITY2 DATA-MANAGEMENT10 DATA-MODELING3 DATABASE3 DATABASE MANAGEMENT1 DATABASE SERVICES1 DATABASE-DESIGN1 DATABASE-MODELING2 DATABASE-PROGRAMMING5 DATABASES3 DEFENSE IN DEPTH2 DENIAL OF SERVICE1 DESIGN3 DIGITAL TRANSFORMATION1 DIGITALGLOBE1 DIRECT MAIL1 DISABLE1 DISASTER PREPAREDNESS1 DISASTER-RECOVERY4 DOD1 DOS ATTACK1 E-COMMERCE2 EARNED VALUE MANAGEMENT1 EC21 ECONOMY1 EMERGENCY PLANNING2 EMPLOYEE TRAINING1 EMPTY1 ENCRYPTION2 ENTERPRISE ARCHITECTURE1 ENTERPRISE SYSTEMS2 ENVIRONMENT1 ENVIRONMENTAL SECURITY1 ESX1 EVM1 FACILITY PROTECTION1 FAIR METHODOLOGY1 FEDERAL AGENCIES1 FEED1 FILE-FORMATS1 FISMA1 FORENSICS1 FULL CONTENT DATA1 FUTURE1 GOOGLE1 GOVERNMENT TECHNOLOGY1 GSM1 HADOOP1 HEALTHCARE1 HEALTHCARE TECHNOLOGY1 IAM1 IDS1 INCIDENT HANDLING1 INCIDENT-RESPONSE5 INFORMATION ASSURANCE16 INFORMATION SECURITY17 INFORMATION SYSTEMS1 INFORMATION TECHNOLOGY1 INFRASTRUCTURE3 INNOVATION1 INSTALLATION1 INTEGRITY MODELS1 INTERNET1 INTERNET INFRASTRUCTURE2 INTERNET OF THINGS1 INTERNET TECHNOLOGY1 INTRUSION DETECTION3 IOT3 IOT SECURITY1 IP ADDRESSING1 IPTV1 ISA-CMM4 ISC2 CERTIFICATION1 ISMS1 ISO 270021 ISO-270011 ISO270011 IT FAILURES1 IT INFRASTRUCTURE3 IT MANAGEMENT1 IT SECURITY1 JUNK MAIL2 LACROSSE1 LACROSSETV.COM1 LEFTHAND NETWORKS SAN1 LEGISLATION1 LOW POWER NETWORKS1 M2M COMMUNICATION1 MANAGEMENT1 MANAGEMENT INFORMATION SYSTEMS1 METHODOLOGY1 MICROSOFT VIRTUAL SERVER1 MILITARY1 MITIGATION1 MOBILE NETWORKS2 MODELING1 MONITORING TOOLS1 NESTED CFLOOP1 NETDUMP1 NETWORK SECURITY4 NETWORK SECURITY MONITORING3 NETWORK TRAFFIC1 NETWORKING2 NETWORKS2 NEW YEAR1 NEW ZEALAND1 NLL1 NORMALIZATION2 NSM TOOLS1 OBJECT ORIENTED1 OBJECT-THEORY1 OPERATIONAL RESILIENCE1 OPT-OUT2 ORACLE7 ORACLE HOME2 ORACLE RAC2 ORGANIZATIONAL CHANGE1 ORGANIZATIONAL SECURITY1 OSI MODEL1 OWASP SAMM2 PACKET CAPTURE1 PENETRATION TESTING1 PERFORMANCE ASSESSMENT1 PERSONNEL SECURITY1 PHYSICAL SECURITY7 POLICY IMPLEMENTATION1 POSTAL SERVICE1 PRIVACY3 PROJECT LIFECYCLE1 PROJECT MANAGEMENT10 PROJECT PLANNING1 RAC5 RE-COMPILE1 RE-INSTALL1 RECYCLE BIN2 RED HAT3 REDHAT2 RELATIONAL-DATABASES4 RELATIONAL-THEORY4 RELINK1 REMOVE ORACLE RAC RE-INSTALL2 REQUIREMENTS-ENGINEERING1 RESEARCH3 RISK ANALYSIS3 RISK ASSESSMENT3 RISK MANAGEMENT11 RISK MITIGATION3 ROUTING1 RSS1 SEARCH ENGINE1 SECURE DESIGN PRINCIPLES1 SECURE DEVELOPMENT2 SECURITY8 SECURITY ARCHITECTURE1 SECURITY ASSESSMENT1 SECURITY AWARENESS3 SECURITY CONTROLS1 SECURITY DESIGN1 SECURITY DOMAINS1 SECURITY ENGINEERING1 SECURITY FRAMEWORKS1 SECURITY LAYERS2 SECURITY MANAGEMENT4 SECURITY METRICS1 SECURITY MODELS1 SECURITY POLICIES2 SECURITY POLICY3 SECURITY RISK ASSESSMENT2 SECURITY TRAINING1 SERVER1 SIMILAR PROCESS1 SMART HOME1 SMART LIVING1 SMS1 SOCIAL ENGINEERING1 SOFTWARE DEVELOPMENT1 SOFTWARE-SECURITY3 SQL2 SQL-TUTORIAL4 STAKEHOLDER ENGAGEMENT1 STOPTHEJUNKMAIL.COM2 SURVEY1 SYSRQ1 SYSTEM REDUNDANCY1 SYSTEMS ENGINEERING3 TEAM COMMUNICATION1 TECHNOLOGY4 TECHNOLOGY ADOPTION1 TECHNOLOGY-COMPARISON1 TELECOMMUNICATION1 TELECOMMUNICATIONS1 THREATS AND VULNERABILITIES1 TRAINING1 TRIPLE CONSTRAINT2 TROUBLESHOOTING1 TRUST1 TWO-FACTOR AUTHENTICATION1 VIRTUAL1 VMWARE1 VSAM1 VULNERABILITY1 VULNERABILITY STUDY2 WEB DEVELOPMENT1
[A~Z][0~9]

Links

Oracle Scripts
Boulder CO,80304
Harman Research
BillBrown.info

Copyright 2005-  BILLBROWN.INFO. All Rights Reserved

to-top