Data Risk Governance

Exploring the intersection between information security, privacy, technology and the law.

Archive for December, 2010

Information Security Policy

Posted by Matt on December 17, 2010

New Policy content added to the Resources section.

Posted in Information Security | Leave a Comment »

SANS Legal 523: Law of Data Security and Investigations

Posted by Matt on December 16, 2010

This past week I’ve had the privilege of attending the one of the nation’s best training events dealing with information security and legal issues. See my review here.

Posted in Information Security | Leave a Comment »

Infected by Malware: Throw the Computer Away?

Posted by Matt on December 16, 2010

There are some forms of malware circulating that infect the persistent memory on graphics processing cards (GPU), network interface cards and any other hardware component that contains its own memory distinct from the computers RAM. This means that you cannot remove the malware simply by reinstalling your operating system after formatting your hard drive, because the malware is located in the memory of one of your hardware components. The difficulty in removing the malware from these locations may just mean you’re better off throwing the computer out and buying a new one! This has been the case for some organizations that have been infected by these types of malware. So much for not hurting the hardware.

http://www.vizworld.com/2010/09/gpuassisted-malware/

Discovered: http://www.theregister.co.uk/2009/03/24/persistent_bios_rootkits/

Posted in Information Security | Leave a Comment »

 
Follow

Get every new post delivered to your Inbox.