Nice quote on security governance of AI
Came across this gem from LinkedIn Learning course by Lyron Andrews.
AI doesn't correct poor governance it simply accelerates existing behavior
Analogy for Generative AI vs Discriminative AI
I've recently been studying ISO/IEC 42001:2023 and came across a great LinkedIn Learning course by Lyron Andrews.
Among the many noteworthy points, Lyron summed the differences well between "Generative AI" learning models and "Discriminative AI" models:
A helpful analogy is that a generative . . .
OWASP Cheat Sheet Series
Security Certification Roadmap
Microsoft Storm-0558 Attack Analysis
I meant to post this earlier but got distracted by a few other things. Yay for busy life, right?
Earlier this month Microsoft concluded their investigation of the recent Storm-0558 email compromise/attack and the results are... fascinating. I highly recommend checking out the blog post when you get a chance. It's available here. . . .
[SC-100] Conditional access "what if" tool
More security controls in the market need a feature like this.
I'm digging the "What If" tool in Azure Conditional Access component. The idea is simple: as you're building policies, you can throw various scenarios at the policy engine to understand what the heck it'll do.
This gives admins the opportunity to observe effects and perhaps test variations of authentication use . . .
[SC-100] Sensitive Operations Report Workbook
Just a friendly reminder that the Microsoft sensitive operations report workbook exists and can be super helpful.
For those unfamiliar, it's an Azure Monitor workbook designed to capture activities/events that could be critical or impactful for Azure AD. Examples include:
- Modified application and service . . .