2021
- Cryptographic controls and feature trade-offs
In an earlier post, I discussed how the use of cryptographic controls can help enable those building privacy governance programs to both deliver on their objectives of meeting their privacy obligations and enabling them…
- Evolution of privacy governance and how cryptographic controls can help
Unfortunately, most organizations do not have a formal strategy for privacy, and those that do usually design and manage them similarly to their existing compliance programs.
- How is ACME different than XCEP/WSTEP anyway?
If you read my blog there is a reasonable chance that you are familiar with <a href="https://tools.ietf.org/html/rfc8555" target="blank" rel="noreferrer noopener">RFC 8555,</a> the standard for Automatic Certificate…
- The next decade of Public Key Infrastructure…
Before we talk about the future we need to make sure we have a decent understanding of the past. X.509 based Public Key Infrastructure originally was created in the late 80s with a focus on enterprise and government use…
- Accountability and Transparency in Modern Systems
Over the last several decades we have seen the rate of technological innovation greatly accelerate. A key enabler of that acceleration has been the move to cloud computing which has made it possible for hardware,…
- Information system security and how little things have changed
When I was a boy my father had me read Plato’s Republic) - he wanted to give an oral report on what the key points of the book were and what my personal takeaways were after reading the book.