can user data be trusted?
Can it be moderated?
tagging, Searching, Sharing/Linking
blogging
audio/podcasting
Video
Wiki
single sign on identity across different site
academic/theoretical models, qualitative methods, quantitative methods
pragmatic methods, COBIT, ITIL, ISM3
standards, ISO 27000-series, NISP SP's, RFCs
professional practice guides, GAISP (? defunct ?)
government directives, NIST 800.x series, DoD 8500.x series, DCID 6/3
business benefits of strong security, doing business safely, understanding the risks, preparing for contingencies, building confidence & trust, enabling business process, supporting business prioritization
Security IS the business
formal (security) methods
security training & awareness for design & development professionals
security architecture, not 'security through obscurity'
competent security testing
speaking, telling security stories, Presentation Skills
writing, persuasive/motivational writing, copy writing
multimedia, combining written & spoken advice, videos plus briefings, website plus plus
bidirectional, gathering feedback, responding positively, engaging hearts & minds
collaborative clusters, academic, industry, professional bodies, standards development
custodianship
governance
influencing the purchaser
closing the deal
internal, the value of security
external, security as differentiator
establishing & building relationships
bringing people together on common interests
special interest groups
collaborating
non-linear thinking, mind mapping?, hyperlinking
critical
structured/scientific analysis
'open source'
seeing downside risks as well as upside opportunities
people
process
technology
remember where we have been
reuse / not reinventing the wheel
current risks, threats, vulnerabilities, impacts
risk management methodologies, quantitative, qualitative
projected/future risks, trends, emerging issues, political, economic, social, technological, new technologies
confidentiality
integrity
availability
Gramm-Leach-Bliley Act
Sarbanes-Oxley Act
HIPAA
Privacy Act
Foreign Corrupt Practices Act
FISMA
CLERP9
Directive 95/46/EC
Bill 198 (CSOX)
PIPEDA
DPA (Europe)