InfoSec

As security professionals, we often talk about taking a layered approach to security when describing the controls we implement to protect information. We understand the need to not have a single point of failure when implementing protection. If a system is processing critical information, we...

Information security programmes are built on assessing risks and understanding what changes are required to make the unacceptable, acceptable. Information security objectives are reached through successful changes that usually overarch whole organisations or whole business units. In a time where the only constant in organisations,...

As an information security professional, I started off my career thinking infosec was all about technical controls - networking; infrastructure; application development. With time, I realised that information security is actually more about the what technical controls you choose to implement and the how you go about doing...

Hey! My name is Diane, and this is my very first blog post on Strategic Security by Diane. In this post I would like to introduce why I have created this space, and what I would like to share through it. My posts will include...