Tuesday, April 20, 2010

A Single Trick for Remembering Passwords

In both our personal and work life we are faced with remembering countless passwords - ATMs, Amazon account, iTunes, the LAN at work. I found this interesting tip for creating secure passwords that are complex to crack but easy for you to remember.

Tuesday, April 6, 2010

Identity Management meets Augmented Reality


Imagine pointing your mobile device/smart phone at a co-worker and seeing a holographic depiction of all the system access assigned to that person. Sound far-fetched? It may be a reality sooner than you think.

Although still experimental, the technology is available. Using face recognition technology to match the person's face with a picture stored on the server, any stored information tied to that profile picture can be sent back and displayed to the requestor.
Imagine an environment where authorized people could perform spot Access Certification checks by simply pointing a mobile device equipped with a camera at a co-worker's face. System access is looked up and displayed in a meaningful way as a holographic image/text floating around that person's face. Think of the possibilities and enterprise use cases this immediate access to information could serve. Read more about this technical capability here:

Sound like an interesting concept? Please comment below to let me know what you think.

Thursday, April 1, 2010

5 Best Practices for Developing a Mobile Strategy

Whether your company has already embraced mobile platforms as a business reality or just getting started, the "next big thing" is here. Here are some best practices to keep in mind when planning your approach to mobile.

1. Know "Why"
One of the first important questions to ask is "Why?" The mobile context is significantly different that the desktop world. What's driving your move to mobile? Simply porting your existing desktop content or creating miniature versions of existing websites for mobile is not a wise move. The content you are providing needs to be useful in the mobile setting. Your end consumer has different needs in the mobile context. As I outlined in previous blog, The 3 Cs of Mobile Website Design, visitor context is a huge factor when considering what to develop.

2. Decide what business functions should be mobilized

What functions will give you the biggest bang for your buck? When determining functionality to port into the mobile context, you want to pick something with a measurable ROI or something that gives your business a competitive advantage. Show value early to help build your business case for expanding into more mobile functionality.


Look at which applications are most important to your company, review your use cases, and re-define how those use cases look on the mobile context. How is the use case different for a mobile user? What's important in the mobile context? Keeping in mind that mobile users want to find not browse.

3. Deploy useful functionality incrementally
This isn't a 6 - 12 month initiative. You need to build and release quickly, solicit feedback, and refine. Think about how to chunk up functionality into small, agile releases. The sooner you get functionality out there the sooner you can start making it more useful. Consider piloting to a limited set of users on specific mobile devices. Start expanding audience and supported devices once it's been around the block a few times and you've had a chance to kick the tires.

4. Develop Standards
As an enterprise it's important to have technical standards in place before they get decided for you. Once the enterprise has momentum with mobile, it's not time to start figuring out what your standards are. Security standards, supported devices are all up for consideration when defining mobile guidelines.

Adopt and adhere to common body of knowledge development best practices. Organizations like the W3C have developed thought leadership and application development standards for mobile.


5. Decide How
App or Mobile website? The answer to this question is important and based on the device capabilities of your end users. If you are targeting an audience that will be using a common device than the robust offerings of a native device application may be the right answer. Native apps allow you to fully exploit the capabilities of the device for an optimal end-user experience. For supporting cross device compatibility a mobile website be the best approach. Although more testing time should be factored in, a mobile website offers widest range of possibilities for a broad user base.

In summary, Mobile is hot, but as with any emerging trend, don't implement technology for technologies sake. Know the audience you are serving, what they want, and what you expect to get out of it - your ROI. Strategic thinking and systematically rolling out mobile capabilities are the keys to success.

Friday, March 5, 2010

5 Tips for Giving a Great Presentation

In my role at Solstice Consulting, I do a lot of presenting on topics that interest me, case studies on project successes, and Solstice's domains of expertise. While my audience has ranged in size and background and the content is different each time, I have found a few prensentation techniques that seem to apply to all situations.

  1. Be confident no matter how unprepared you feel. Projecting confidence is a sure fire way to build credibility with your audience and help ease your nerves.
  2. Dress smart and confident. What you wear impacts how you feel about yourself. Splurge on that smart suit or stylish shirt.
  3. Be interesting and engaging. Pull people into your world with stories, anecdotes, and humor. The more they laugh, the more they'll like you, and the more they will remember you.
  4. Read the room and get a pulse on the audience. When you feel things are going south and people loosing interest, start asking them questions to keep them engaged. Get them talking and learning from each other. Your audience will appreciate your facilitating knowledge sharing. And they might have the content or answers that you don't.
  5. Keep the slides light on text. The more text the more tempted you are to read directly from the slide. Use key phrases and words. This helps keep the presentation conversational when you use your own words and stories to deliver the content.

As always, I'd love to hear your thoughts. What are some techniques that work for you?

Tuesday, March 2, 2010

The Information Security Profession: Today and Beyond

The information security profession is changing. I've been asked to present my perspective at NetSecure on how the profession is changing and what's driving the change. If you can't make it to the event, here is a sneak preview of my presentation.

Monday, February 1, 2010

Shedding Light on the Information Security Landscape: An Interview with Sandra Toms LaPedis, Area Vice President and General Manager, RSA Conference

The Information Security landscape is changing. In the face of dealing with more sophisticated threats, these recessionary times are driving innovation like never before. Sandra Toms LaPedis, Area Vice President and General Manager, RSA Conference , sheds light on information security challenges, technology trends driving the CSO agenda, and how today’s environment is creating opportunities.

1. What are the top organizational challenges facing security professionals today?
The number one challenge is that IT departments are currently working with fewer resources. While Gartner research shows that IT budgets will be up in 2010 by 3.3 percent, the industry will still be playing catch-up with 2009’s 5.2 percent decrease. And according to the U.S. Bureau of Labor Statistics, 9.4 percent of the population is currently without a job – with California being hit particularly hard at a rising 12.4 percent. Unfortunately, many security practitioners are in these ranks.

With these limited resources and the loss of talented security professionals in IT departments across the country, no one is minding the proverbial store. Many organizations are left with stripped-down departments that have fewer people watching for threats. We know more issues can occur during these times of economic hardship, so having more eyes on the security posture of an organization is more important than ever before.

2. What are the top three technology concerns for organizations?

Based on the abstracts that were submitted and the agenda we have set for RSA Conference 2010, we see that three particular areas of concern are cloud security, security in the face of consumerization and mobility and cyber warfare.

3. How is today's business environment impacting how security challenges are addressed?

In July 2009, we surveyed nearly 150 C-level executives and professionals charged with directing, managing and engineering security infrastructures within their respective organizations to find out their pain points for the coming 12 months. Fifty-seven percent of respondents cited budgetary constraints as their biggest concern. This means organizations have to get creative with the way they protect their infrastructure since they have fewer dollars to spend. This may include finding new tools that address multiple issues, learning how to make what they currently have adapt to changes in the landscape or architecting new solutions.

4. How has the current environment created opportunities for security-focused service providers? Is today's environment driving innovation?

Recessionary periods drive the most innovation. Especially today, when entrepreneurs and developers have so much technology to get them started, industrious individuals are required to be more creative and resourceful. You can simply look at events like TechCrunch50 and DEMO to see that technology professionals are capitalizing on missed opportunities by debuting truly innovative products and solutions.

The information security industry is no exception. Codes are becoming more malicious, botnets are getting smarter and attacks on corporations and nation states have become more frequent – such an environment is ripe for information security innovation. At our Innovation Sandbox program we showcase and honor companies and individuals that are at the cutting edge of security innovation and have the most promise for offering a solution to the information security industry’s most pressing issues. On February 8 we will select 10 finalists from a pool of 40+ submissions to compete for the title, “Most Innovative Company at RSA Conference 2010.” With this program we plan to highlight the entrepreneurial spirit of the security industry while also giving early stage companies a venue to be seen by their peers.

5. What have you seen in terms of innovation in security?

In the last year we’ve seen new companies address the security concerns associated with the proliferation of cloud computing and virtualization in IT architectures, as well as significant advances in the way organizations can secure their employees’ mobile devices. The list goes on and on, but there is a need for so much more – which is why Innovation Sandbox is such an important program, and why information security professionals sharing best practices at RSA Conference becomes a business imperative.

This year we’ve had companies submit products that can emulate a phishing attack on an employee to provide education on how to identify risks via email, solutions that address the security risks associated with password resets and products that have turned authentication as we know it on its head by integrating image recognition to the fold.

Sandra Toms LaPedis, Area Vice President and General Manager of RSA Conferences, joined the company in 1998 and is responsible for the global promotion and successful execution for the Conference. This includes content, strategy, logistics, industry relations, brand extensions and partnerships.

Monday, January 25, 2010

4 Point Plan for Testing Mobile Websites

When building a website targeted for mobile platforms, having a good testing strategy is one of the keys to ensuring end-user satisfaction. The mobile context is different than desktop. With so many different devices with varying capabilities it can be challenging to develop functionality that works well on all. Here's a 4 point strategy to use when determining how to test your mobile website:

1. Define testing scope
There are many variables at hand when considering the mobile context - device capabilities, operating system, propietary browsers, carrier network performance - it's difficult to test every aspect thoroughly. Mobile testing is about focusing your efforts. Hone in on your intended audience, do your homework on devices the majority of your end-user base will be using. Build a testing plan around your target audience's device hardware, operating system, browser, and network. Utilize alternatives to native device testing to cover other user populations (i.e. mobile test emulators, see below).

2. Test functionality first on a desktop
Get the functionality working first then focus on cross device, cross operating system compatibility. Dealing with all the possible issues at once - basic functionality, OS and browser specific graphic design issues - can be time consuming. Keeping your testing focused on functionality first then look and feel and navigation will avoid wasted energy.

3. Utilize mobile emulators

Once the functionality works as expected, test the user experience on emulators. Emulators exist to test specific operating systems, browsers, and devices. If you aren't familiar, emulators run on your desktop and emulate the mobile OS and mobile browser environment. Here are a few of the most popular:

It's not always a slam dunk installing these so be sure to allocate time for installing all required components and configuration.

The W3C also has a great resource for validating the mobile friendliness of a website. As mentioned in my previous blog - 3 C's in Moble Website Design - The World Wide Web Consortium (W3C) is founded on the principles that the web should be accessible to all and on as many devices as possible. To realize this, the W3C body of knowledge has developed technical standards and best practices for the development, design, and content authoring. Simply enter your website URL into the W3C MobileOK checker and the checker validates your site against the mobile best practices as defined by the W3C.

4. Test on native devices
Finally, execute testing on the native devices, operating systems, and browsers outlined in your testing plan. At this point all functionality issues should be worked out and your testing is focused on user experience and useability on specific devices.

The basic principles of desktop application testing apply to the mobile web context as well. A good plan and focused execution will help reduce post-production issues and eliviate end-user frustration.

What are you doing to test your mobile websites? Comments and discussion welcome!