Skip to main content

Posts

What Is software testing?

Software Testing Software testing is the process of evaluation a software item to detect differences between given input and expected output. Also to assess the feature of A software item. Testing assesses the quality of the product. Software testing is a process that should be done during the development process. In other words software testing is a verification and validation process. Verification Verification is the process to make sure the product satisfies the conditions imposed at the start of the development phase. In other words, to make sure the product behaves the way we want it to. Validation Validation is the process to make sure the product satisfies the specified requirements at the end of the development phase. In other words, to make sure the product is built as per customer requirements. Basics of software testing There are two basics of software testing: blackbox testing and whitebox testing. Blackbox Testing Black box testing is a testing techniqu...

Developing Risk Management Plan

Developing an effective Risk Management Plan can help keep small issues from developing into emergencies. Different types of Risk Management Plans can deal with calculating the probability of an event, and how that event might impact you, what the risks are with certain ventures and how to mitigate the problems associated with those risks. Having a plan may help you deal with adverse situations when they arise and, hopefully, head them off before they arise. 1.       Understand how Risk Management works.   Risk is the effect (positive or negative) of an event or series of events that take place in one or several locations. It is computed from the probability of the event becoming an issue and the impact it would have (See Risk = Probability X Impact). Various factors should be identified in order to analyze risk, including: ·          Event: What could happen? ·        ...

Cyber Security versus Information Security

The key difference is that information security is mainly relevant to personal information while cyber security is more universal, focusing on other concerns such as our national infrastructure. My feeling though … is that information security is actually a super-set of cyber security since anything in the cyber realm would involve information or information systems. As usual here is my  pseudo-Venn diagram to enjoy. Then we have the official NIST definitions from IR 7298 Revision 2. They define cyber security and information security as follows (note there are two definitions for information security). Cybersecurity:  The ability to protect or defend the use of cyberspace from cyber attacks. Information Security (1):  The protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. Information Security (2): ...

What is a risk assessment?

“….a careful examination of what, in your work, could cause harm to people, so that you can weigh up whether  you have taken enough precautions or should do more to prevent harm….” Why do a risk assessment? A risk assessment will protect your workers and your business, as well as complying with law A person from your organisation needs to attend risk assessment training as it will ensure that this person is competent within your organisation and will gain abilities such as hazard identification, ability to categorise and evaluate risk(s). These abilities will allow a ‘suitable and sufficient’ risk assessment to be conducted within your own organisation.   How to do a risk assessment There are no fixed rules on how a risk assessment should be carried out, but there are a few general principles that should be followed. Five steps to risk assessment can be followed to ensure that your risk assessment is carried out correctly, these five steps are: 1. ...

Best Network Security Practices in 2017

          Collect Detailed Logs For a complete record of what goes on in your systems – both for security and troubleshooting purposes – you should collect detailed logs and report data. This is especially the case for applications that don’t have internal logging. By adding tools that can log the activities of these applications you will be able to plug any security holes those applications may create. Maintain Security Patches When cyber-criminals are constantly inventing new techniques and looking for new vulnerabilities, an optimized security network is only optimized for so long. When Home Depot’s POS systems were hacked last summer, they were in the process of installing a security patch that would have completely protected them. To keep your network protected, make sure your software and hardware security is up to date with any new antimalware signatures or patches. Beware of Social Engineering All of the technical IT security ...

ISO 27001 vs. ISO 27032 cybersecurity standard

Antonio Segovia There are many standards in the ISO 27001 series, all related to security.  You probably don’t know much about ISO 27032:2012 because it is not as well-known as ISO 27001, ISO 27002, or ISO 22301, but it is near you, because it has to do with a place that you habitually visit: cyberspace. The word “security” is a complex term that involves various disciplines, and it is composed of various domains, like application security, network security … and cybersecurity. So, cybersecurity is not synonymous with information security, application security, network security, etc. The main objective of cybersecurity is to require stakeholders to play an active role in the maintenance of cyberspace (i.e., it requires actions that stakeholders should be taking to establish and maintain security in cyberspace) and in the improvement of its reliability and utility. Cybersecurity and cyberspace First, a few basic things. What is cyberspace? It’s the virtual pl...

Network Security

Business security is becoming a much bigger challenge for today’s companies due to rapid advancements in technology and an ever-evolving marketplace. Team Logic IT provides your business with the end-to-end security solutions that safeguard your information at all levels – from user end points to the server and networking layers. Our multi-layered approach to network security is the offense and defense needed to protect your company on today’s playing field . Security Breaches Businesses large and small suffer similar concerns when it comes to vulnerabilities associated with viruses, spam attacks, firewall breaks and more. TeamLogic IT follows industry best practices, policies and procedures to assess threats to your operations and provide you with a customized security solution that protects the usability, integrity and reliability of your network. 24/7 Remote Monitoring You and your staff can’t oversee your computers and servers 24/7, but TeamLogic IT can. Our Re...