* ‘Security on a Budget’ lecture available online
endif; ?>Two years ago Network World Germany asked me to present a lecture entitled “Security on a Budget” to a conference it organized. I was teaching undergraduate courses on the day of the conference, so I couldn’t be in Germany then, but I did arrange to lecture via Vermont Interactive Television.
My “IS340 Intro to IA” students piled into a van with me and we drove a few miles up Interstate 89 to Waterbury, Vt., where we sat in a pleasant studio with several cameras and microphones. In a jiffy, we were connected to the organizers and audience in Germany. They could see and hear us; we could see and hear them.
In my lecture and the accompanying paper, I went over the basics of information assurance and reminded participants that if poor security practices allow damage to our systems, we may be subject to criminal or civil legal proceedings. Indeed, if our negligence allows third parties to be harmed via our compromised systems, there may be even more severe legal problems.
Another issue emerging in e-commerce is that good security can finally be seen as part of a market development strategy. Consumers have expressed widespread concerns over privacy and the safety of their data; companies with strong security can leverage their investment to increase the pool of willing buyers and to increase their market share. We no longer have to look at security purely as loss avoidance; in today’s marketplace good security becomes a competitive advantage that can contribute directly to revenue figures and the bottom line.
As all security experts today agree, security, like quality, is a process, not a static result. With the constant change in technology in today’s world, it is inevitable that there will be new threats and vulnerabilities all the time. However, security need not be a terribly expensive, complicated process. On the contrary, there are some major benefits available from relatively inexpensive measures such as improving corporate culture and implementing defense in depth using relatively simple techniques.
The Vermont Interactive Television crew kindly gave me a videotape of the event. Some months ago, in discussion with our instructional-technology staff at Norwich University, I asked if the sound track could be converted to a digital format; they quickly gave me an 8M-byte MP3 file.
I have placed the original PowerPoint file, the MP3 file and a PDF file with a review article on my Web site. Simply visit the home page for a pointer in the “New to the site” section: https://www2.norwich.edu/mkabay
If you do listen to the MP3 file, you might want to skip the first 7.5 minutes unless you speak German; however, after that you will hear my high-pitched, over-inflected voice merrily lecturing in English for the next 40 minutes or so. Feel free to use the materials freely for non-commercial use – but, as usual, please don’t post them anywhere else on the Web (it’s too hard to correct errors in multiple copies). Remember that you don’t have to ask for my permission to use my stuff for internal use; I copyright it precisely so I can give it away for non-commercial applications.
I hope you will enjoy the lecture and that you can use it in your internal training for new employees or for executive-level new hires who need a grounding in the basics of information assurance management.




