Inauguration Security: Lessons Learned

As most of us know, yesterday hundreds of thousands of people converged to witness the swearing in of the 44th president of the United States, Barack Obama. My television was on in the background yesterday, and my radar couldn’t help but pick up on some of the...

Patching Beyond Microsoft

Oracle released 41 security patches this week for a variety of their products. Ten of the patches were for the Oracle database – – that by the way is used in many SCADA and DCS servers. We have seen great progress with vendors testing and certifying...

Are the Bandolier Security Audit Files Making the Grade?

Based on the reviews from early adopters, the Bandolier security audit files exceeded many expectations in 2008, including my own. We have received some very encouraging feedback from vendors, asset owners, consultants, and even our own assessment teams. With each new...

Latest Research On Embedded System Security

Embedded device security is a topic that many will dismiss, in favor of more popular security concerns. I can understand this, to a certain extent, because mainstream press and information outlets often do not cover embedded security. They are focused on the more...

‘Functional’ Programming Paradigm & Control System Security

The gist of discussion on my earlier blog on the “Relative Security of the ARM vs. x86 architectures” can be summarized in two bullets. 1.  It is interesting that at least theoretically, a proper Harvard Architecture based chip might provide a better...