Home Information Security
Information Security
Cancel

Information Security

Previous Posts


InfoSec Best Practice - An Unhelpful Term

A short piece about the term “Information Security best practice, and how it’s harming our industry.

October 04, 2023 3 min

A Rant about DevSecOps

A rant about running vulnerability management programmes that work.

Feburary 27, 2023 3 min

Vulnerability Management in 4 Stages

A rant about running vulnerability management programmes that work.

June 07, 2022 14 min

Information Security Risk Management - Benefits & Common Pitfalls

How Information Security Risk Management can practically and significantly improve the security posture of your organisation.

Dec 31, 2021 16 min


Planned Posts

TitleDescription
Microservice architecture isn’t a panaceaA pragmatic look at the pros and cons of different architectural patterns
Malware Analysis IntroMy first impressions of getting into malware analysis and reverse engineering


Helpful Resources

VxUnderground

  • Virus Exchange Underground, the largest collection of malware source code, samples, and papers on the internet.

Awesome Hacking - Github list

  • A great and exhaustive list of all things infosec. have an explore and find some treasure.

Awesome Security News Letters - Github list

  • A good list of security newsletters. Some better than others. Personally, I really like Ollie Whitehouse’s ‘Bluepurple Pulse’, Clint Gibler’s ‘tl;dr sec’ newsletter and Zack Whittaker’s ‘This Week in Security’.

Awesome Cloud Security - Github list

  • A good list of resources related to all things Cloud Security.

Alien Vault - Open Threat Exchange (OTX)

  • An open source threat intelligence feed and threat data platform that allows security researchers to investigate new threats.

OpenVAS - Open Vulnerability Assessment Scanner

  • An free & full-featured network, system/server and application vulnerability scanner.

Gophish

  • An open-source phishing framework that makes it easy to test your organization’s exposure to phishing.

Snyk.io

  • Snyk is a developer friendly tool that tests for vulnerabilities in code, open source dependencies, container images and infrastructure as code configurations.

SANS Information Security Policy Project

  • A repository of very useful policy templates.

Publicly Available ISO Standards

  • A repository of free ISO standards to download.

Secure Control Framework’s List of Security Domains

  • A repository of InfoSec Domains including information about each.