My wife says to me, “I seem to be getting your junk mail. Somebody just sent me Data Security Quiz results.” I have no idea what she means, so she forwarded me the email from the National Information Security Assocation (NISA). I confess that I had never heard of this organization before, and I really don’t know what they do. Apparently they quizzed a number of real estate agents and brokers around the country to find out how much they knew about data security. The results were emailed as a way of educating real estate professionals at large. Color me shocked. Actually, I thought the questions were pretty good to be asking for sales people. The Q&A was as follows:

  1. According to industry standard practices, when is it safe to leave sensitive client information in your car (either in electronic form, such as a laptop or in paper form)? Answer: d) Never.
  2. Which tool is most important once a network breach has been discovered? Answer: c) Access Log
  3. For most workplace computers when is it possible to be infected with malicious software? Answer: a) Anytime the computer is on.
  4. If I only collect client data for a short sale processing company, I am not responsible for data leaks? Answer: False
  5. What are the only actions that can guaranty the security of client data? Answer: c) There is no way to guaranty data security.
  6. What is the one sure method to determine if your computer contains malicious software? Answer: b) There is no way to be 100 percent sure.

Question three actually cracked me up because it is so true! I think there is a little bit of FUD going on here to get people to attend a seminar, because the email talks about blended threats and Stuxnet. I know real estate agents are pretty pissed about the state of the economy, but I am pretty sure plutonium enrichment is not a general concern. Regardless, it is very interesting to see how much security awareness training and security bullitens are being distributed to real estate professionals. Like Rich’s mention a few weeks ago that the owner of the local coffee shop was aware of PCI-DSS. The times they are a-changin’.

One final note: It appears we have SOLD OUT the Cloud Security Training course we are offering February 13th. If you are still interested, let us know and we will see if we can find a bigger room. Probably not, but we will see what we can do. Given the interest in the material, we are looking at providing more classes in the coming months so it helps us if you let us know if you are interested in cloud security certification.

Remember, for every comment selected, Securosis makes a $25 donation to Hackers for Charity. This week’s best comment goes to Joshua Corman, in response to Good Programming Practices vs. Rugged Development.


Rugged is a Value. A characteristic. An Attribute. A Quality. A State.

Rugged in its simplest sense is an affirmative, non-security-executive desirable. Security is a negative – a Cost/Tax and usually an inhibitor to what a CIO wants.

Rugged encapsulates things like:

…that the CIO already wants.

For your eCommerce, do you want a flimsy Hosting Site? or a Rugged Hosting site?

Communities like OWASP can help developers to affect more Rugged outcomes. Jeff is involved in Rugged.

Rugged is on the overlooked People level more heavily than on the process and tech level.

We have a lot of great tools and technology and frameworks (sure we could use more and better ones). What’s most been lacking is Mainstream awareness and demand for the value of Rugged.

In my 11/12 months, I’ve seen the most traction for Rugged on those buying software. on Demand. If we can drive sufficient Demand, Supply will often follow.

I’m still looking to connect with you 1 on 1.

For now think of Rugged as what people want/need/deserve, and thing like OWASP, Agnitio, etc as ways people can help them to pursue.