Posts

Showing posts from November, 2019

RFID explained

Image
When non-tech savvy people think about security, they may picture security cameras, guards, or even biometric security measures. Cybersecurity professionals may think of firewalls or intrusion monitoring when asked about their idea of security, and physical security is pushed to the side. Recently, I’ve been testing the physical security measures of my employer and one interesting thing I found is that RFID copying tools are available and cost as little as 20 dollars. I purchased one of these tools and began testing our RFID cards and, while it wasn’t able to copy our cards, it can be difficult to understand. RFID may not be new, but it’s a complex technology that tends to go unnoticed. Radio Frequency Identification (RFID) utilizes electromagnetic fields to track a corresponding device (card, tag, etc.). There are two main kinds of RFID tags; active and passive. Passive tags do not have their own power source, and pulls energy from the reader. Since the tag does not have its own...

NIST Cybersecurity Framework

Image
The National Institute of Standards and Technology (NIST) cybersecurity framework is a policy framework to guide users in the private sector to assess and improve their prevention, detection, and response abilities when it comes to cyber-attacks. It is primarily used in the United States, however, it has been translated to many different languages and is used by the Japanese and Israeli governments. The version 1.0 framework was originally published in 2014 to be used by managers and operates of critical infrastructure elements. Now, it is widely used by businesses and organizations to assist with becoming more proactive with risk management. Version 1.1 of the framework was drafted in 2017 and made public on April 16 th , 2018. This version included changes regarding self-assessments, interactions with stakeholders, supply chain risk management, and the vulnerability disclosure process. The core material of the NIST cybersecurity framework is divided into five main categories wh...